PT-2019-13399 · Medtronic · Medtronic Valleylab Ft10 Energy Platform+1
Published
2019-11-08
·
Updated
2020-10-09
·
CVE-2019-13535
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Medtronic Valleylab FT10 Energy Platform versions 2.1.0 and lower
Medtronic Valleylab FT10 Energy Platform version 2.0.3 and lower
Valleylab LS10 Energy Platform versions 1.20.2 and lower
Description
The issue concerns the RFID security mechanism, which fails to apply read protection. This allows for full read access of the RFID security mechanism data.
Recommendations
For Medtronic Valleylab FT10 Energy Platform versions 2.1.0 and lower, consider restricting access to the RFID security mechanism until a fix is available.
For Medtronic Valleylab FT10 Energy Platform version 2.0.3 and lower, restrict access to the RFID security mechanism until a fix is available.
For Valleylab LS10 Energy Platform versions 1.20.2 and lower, restrict access to the RFID security mechanism until a fix is available.
Fix
Incorrect Permission
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Medtronic Valleylab Ft10 Energy Platform
Valleylab Ft10 Energy Platform